Software supply-chain abuse remained prominent as a malicious npm package impersonating a WhatsApp Web API library surpassed 56,000 downloads. The package intercepted messages, contacts, media, and authentication tokens while covertly linking attacker-controlled devices to victims’ WhatsApp accounts.
Nation-state espionage activity resurfaced with the return of Infy (Prince of Persia), an Iranian-linked threat actor dormant for several years. Researchers identified new Foudre and Tonnerre malware variants, expanded command-and-control infrastructure, and continued targeting across Europe and the Middle East.
Phishing operations increasingly relied on automation, with AI-powered website builders enabling large volumes of realistic scam sites. Researchers observed hundreds of newly generated phishing pages daily, cloning financial, cryptocurrency, and e-commerce brands with minimal technical effort.
On the defensive side, Docker released more than 1,000 Docker Hardened Images as free and open source, providing minimal base images, verifiable provenance, and reduced attack surface for containerised applications.
Service reliability and legacy tooling also drew attention after Google confirmed the shutdown of its Dark Web Report alert service. Separately, a NIST attempt to disable Network Time Protocol infrastructure following an atomic clock drift incident highlighted operational sensitivity in time synchronisation systems.
Today’s selected highlights expand on the malicious npm WhatsApp spyware, the resurgence of the Iranian Infy APT, Docker’s hardened container images, and the rise of AI-generated phishing websites.
A malicious npm package disguised as a WhatsApp Web API library accumulated more than 56,000 downloads before being identified as spyware. The package secretly intercepted messages, contacts, media, and authentication tokens, while also linking attackers’ devices to victims’ WhatsApp accounts through a hidden backdoor. Its functional code, heavy obfuscation, and persistence mechanisms allowed it to evade detection for months.
Researchers have identified renewed and expanded activity from the Iranian-linked “Prince of Persia” threat group after several years of apparent inactivity. The campaign uses updated Foudre and Tonnerre malware variants, multiple command-and-control servers, and Telegram-based infrastructure to manage victims and exfiltrate data across Iran, Europe, and beyond. Analysis shows increased operational scale, more complex domain generation techniques, and continued targeting aligned with long-running state-sponsored espionage objectives.
Docker has made its hardened container images freely available and open source, expanding access to security-focused base images across the container ecosystem. The images are designed to reduce attack surface, provide transparent vulnerability data, and include verifiable build provenance, while remaining compatible with common Linux distributions. The move reflects Docker’s broader effort to strengthen software supply chain security amid growing container adoption.
Researchers report a sharp rise in phishing and scam sites created using AI-powered website builders that can clone trusted brands with minimal effort. These tools enable realistic, localised replicas of banking, cryptocurrency, and e-commerce sites, significantly lowering technical barriers for fraud operations. Analysis indicates hundreds of new AI-generated malicious websites appearing daily across multiple regions.